Skip to main content
All configuration options for OpenSRE can be set via environment variables. This page provides a complete reference.

Secret storage

Environment variables are checked first. Credentials you enter through opensre onboard or opensre integrations setup are written to .env and to an owner-only file at ~/.opensre/credentials.json (mode 0600). OpenSRE does not write secrets to the OS keychain. A value in the process environment or a local .env file wins over the credentials file. Keep .env out of source control. Want credentials only from the environment, never on disk? Set OPENSRE_DISABLE_KEYRING=1 and export everything yourself.

LLM providers

LLM Reasoning Effort

CLI investigation tools

Output & Debugging

Credentials and authentication

For secrets (*_TOKEN, *_KEY, *_PASSWORD, *_SECRET, and similar), OpenSRE looks in this order:
  1. Your process environment
  2. The owner-only file ~/.opensre/credentials.json
opensre onboard saves credentials there so they still work after you clear .env. Not stored as secrets: webhook-style URLs such as SLACK_WEBHOOK_URL and ROCKETCHAT_WEBHOOK_URL. Those stay in env / store only — treat them as secrets and don’t log them. Want credentials only from the environment, never on disk? Set OPENSRE_DISABLE_KEYRING=1 and export everything yourself.

Telemetry & Monitoring

Paths & Directories

Memory

Remote sync

Mirror conversation history and memory to a user-owned object store. Details: Remote sync.

Masking

Feature Flags

Integration credentials

Multi-instance integrations

Need more than one Datadog, Grafana, or AWS account (for example prod and staging)? Use a JSON *_INSTANCES variable: Format and examples: Multi-instance integrations.

LLM classification models

If you don’t set these, OpenSRE falls back to the reasoning model (or the provider default):